|
246601
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible Use-after-free issue in Media Codec process. Any application using codec…
|
CWE-416
Use After Free
|
CVE-2018-11261
|
2024-11-21 12:43 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246602
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a fast Initial link setup (FILS) connection request, integer overflow may l…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11260
|
2024-11-21 12:43 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246603
|
8.8 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
|
NVD-CWE-noinfo
|
CVE-2018-11766
|
2024-11-21 12:43 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246604
|
7.5 |
HIGH
Network
|
apache debian redhat
|
tomcat_jk_connector debian_linux jboss_core_services
|
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge…
|
CWE-22
Path Traversal
|
CVE-2018-11759
|
2024-11-21 12:43 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246605
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware …
|
When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, …
|
CWE-416
Use After Free
|
CVE-2018-11305
|
2024-11-21 12:43 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246606
|
5.5 |
MEDIUM
Local
|
puppet
|
cisco_ios
|
Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 r…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11752
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246607
|
6.5 |
MEDIUM
Network
|
puppet
|
cisco_ios_module
|
Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.
|
CWE-20
Improper Input Validation
|
CVE-2018-11750
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246608
|
7.8 |
HIGH
Local
|
puppet
|
device_manager
|
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11748
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246609
|
5.9 |
MEDIUM
Network
|
apache canonical redhat oracle netapp
|
http_server ubuntu_linux enterprise_linux retail_xstore_point_of_service hospitality_guest_access enterprise_manager_ops_center secure_global_desktop instantis_enterprisetrack
|
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This…
|
NVD-CWE-noinfo
|
CVE-2018-11763
|
2024-11-21 12:43 |
2018-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246610
|
8.8 |
HIGH
Network
|
samsung
|
samsung_members
|
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-priv…
|
NVD-CWE-noinfo
|
CVE-2018-11614
|
2024-11-21 12:43 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|